Galvafy Studio & Academy
Privacy Policy
How we handle personal information for creators, learners, and organizations using Galvafy Studio and Galvafy Academy.
Last updated: July 20, 2026
1. Who we are
Galvafy operates Galvafy Studio (course creation) and Galvafy Academy (learning experience). Authentication, organization accounts, and subscription billing are provided through Galvafy Core. This policy covers personal and learning data processed in Studio and Academy.
Questions: privacy@galvafy.com. For security incidents, see our Trust & Security page.
2. Data we collect
- Account data — name, email, profile details, and authentication identifiers managed via Galvafy Core.
- Workspace & org data — membership, roles, invites, and plan entitlement metadata needed to gate features.
- Creator content — courses, chapters, media, sources, and publishing metadata uploaded or generated in Studio.
- Learner records — enrollments, progress, quiz attempts, certificates, notes, assignments, and related completion history in Academy.
- Usage & product telemetry — feature usage, AI token metering events, and operational logs needed to run and secure the service.
- Support communications — messages you send us about the product.
3. How we use data
- Provide Studio authoring and Academy learning features you request
- Enforce workspace isolation, roles, and plan limits
- Generate or assist content when you use AI features
- Issue certificates and track completion for assigned learning
- Operate billing and entitlements with Galvafy Core / Stripe
- Maintain security, prevent abuse, and improve reliability
- Comply with law and respond to lawful requests
4. Where data is stored
Application servers and primary databases for Studio and Academy are hosted on DigitalOcean infrastructure in the United States. Course assets and media are stored in S3-compatible object storage (default region configuration is US-based). Identity and subscription records may also be held in Galvafy Core under the same United States operational footprint unless otherwise agreed in a written enterprise arrangement.
Details for HR and compliance buyers — including access boundaries and breach posture — are summarized on the Trust & Security page.
5. Sharing and subprocessors
We do not sell personal data. We share data with subprocessors only as needed to run the product, including:
- Hosting and database providers (DigitalOcean and related infrastructure)
- Object storage for media and packages
- Payment processing via Stripe (through Galvafy Core billing)
- AI model providers (for example Anthropic and OpenAI) when you use generation, tutoring, transcription, or image features — prompts and necessary context are sent to those providers to fulfill the request
- Email delivery and error/analytics tooling when configured
6. Access within Galvafy
Workspace Owners and members see data according to product roles. Galvafy personnel access customer data only for support, security, or operations, under least-privilege controls — not for unrelated browsing of learner records.
7. Retention and deletion
We retain account and learning records while your organization uses the service and for a reasonable period afterward for backups, dispute resolution, and legal obligations. Signed-in users can export personal data and request account deletion from Settings → Privacy & data in Studio or Academy.
8. Your choices
- Update profile and notification preferences in product settings
- Export a copy of your personal learning/account data
- Request account deletion (subject to workspace-owner blockers where applicable)
- Contact privacy@galvafy.com for other privacy requests
9. Changes
We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date on this page.